Compliance & Certification Readiness
Last reviewed: July 29, 2026. This is a self-assessment and readiness record, not legal advice, an external audit, or a certification claim.
Certification status
| Area | Status | Evidence and remaining work |
|---|---|---|
| Privacy controls | Implemented controls | Published collection purposes and retention periods; IP addresses excluded from analytics; access to analytics is restricted; automated deletion schedules are implemented. |
| PIPEDA readiness | Partial | Technical safeguards, openness, collection limits, and retention controls exist. The operator must appoint and publish a privacy contact, establish access/correction and complaint procedures, maintain breach records, and obtain legal review before claiming compliance. |
| Accessibility | Automated checks passed | Keyboard, semantic, responsive, colour-contrast, and static accessibility checks are part of the test suite. Manual screen-reader and disabled-user testing and an external WCAG audit remain outstanding. |
| Security | Hardened; not certified | HTTPS, restrictive security headers, same-origin checks, input validation, rate limiting, file-signature checks, retention, and protected administration are implemented. No SOC 2, ISO 27001, PCI DSS, or independent penetration-test certification is claimed. |
| CASL | Not currently used | The service does not operate a promotional email or SMS program. Before adding one, the operator must implement consent records, sender identification, and a working unsubscribe process. |
Applicable guidance
- PIPEDA fair information principles
- Ontario web accessibility guidance
- Canada's Anti-Spam Legislation guidance
Release evidence
Each release is checked for formatting, syntax, application health, security controls, data handling, rooms, moderation, file transfer, browser behaviour, accessibility, load, reconnects, and deployment errors. Passing automated tests reduces risk but does not establish legal compliance or third-party certification.